Vulnerability Name:

CVE-2021-31607 (CCN-200624)

Assigned:2021-04-17
Published:2021-04-17
Updated:2022-05-03
Summary:In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-78
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2021-31607

Source: XF
Type: UNKNOWN
saltstack-cve202131607-priv-esc(200624)

Source: CCN
Type: salt GIT Repository
SaltStack Salt

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211110 [SECURITY] [DLA 2815-1] salt security update

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-158e9c6eb9

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-93a7c8b7c6

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-5aaebdae8e

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-00ada7e667

Source: CCN
Type: stealthcopter Web site
CVE-2021-31607 SaltStack Minion Privledge Escaltion in Snapper Module

Source: MISC
Type: Exploit, Patch, Third Party Advisory
https://sec.stealthcopter.com/saltstack-snapper-minion-privledge-escaltion/

Source: DEBIAN
Type: Third Party Advisory
DSA-5011

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-31607

Vulnerable Configuration:Configuration 1:
  • cpe:/a:saltstack:salt:*:*:*:*:*:*:*:* (Version >= 2016.9 and <= 3002.6)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8035
    P
    libprotoc20-3.9.2-150200.4.19.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8092
    P
    salt-transactional-update-3005.1-150500.2.13 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7969
    P
    libvpx4-1.6.1-150000.6.8.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7658
    P
    librrd8-1.7.0-6.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8078
    P
    gv-3.7.4-1.41 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7784
    P
    python3-salt-3005.1-150500.2.13 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7676
    P
    libssh-config-0.9.6-150400.1.5 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8080
    P
    java-1_8_0-openjdk-1.8.0.362-150000.3.76.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:728
    P
    Security update for php-composer2 (Important)
    2022-09-05
    oval:org.opensuse.security:def:721
    P
    Security update for postgresql13 (Important)
    2022-09-01
    oval:org.opensuse.security:def:3629
    P
    Security update for python3 (Important)
    2022-07-11
    oval:org.opensuse.security:def:3622
    P
    Security update for apache2 (Important)
    2022-07-06
    oval:org.opensuse.security:def:3522
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3537
    P
    kdump-0.8.16-9.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3444
    P
    bind-9.11.2-3.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3181
    P
    libgssglue1-0.4-3.76 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94556
    P
    gc-devel-7.6.4-1.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95167
    P
    salt-transactional-update-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:94811
    P
    python3-salt-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95152
    P
    salt-api-3004-150400.6.16 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:99486
    P
    (Important)
    2022-02-18
    oval:org.opensuse.security:def:113236
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:99685
    P
    (Moderate)
    2021-10-20
    oval:org.opensuse.security:def:106653
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:99993
    P
    (Moderate)
    2021-09-18
    oval:org.opensuse.security:def:101269
    P
    gradle-4.4.1-1.87 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:111594
    P
    Security update for salt (Critical)
    2021-07-11
    oval:org.opensuse.security:def:111578
    P
    Security update for salt (Important)
    2021-07-11
    oval:org.opensuse.security:def:111447
    P
    Security update for salt (Critical)
    2021-06-23
    oval:org.opensuse.security:def:70246
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:100301
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:38440
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:69058
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:102797
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:118502
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:42873
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:99287
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:94176
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:10287
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:8608
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:92145
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:101459
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:69492
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:109406
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:64718
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:76527
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:96107
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93570
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:9537
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:92934
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:1570
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:70427
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:20609
    P
    Security update for Salt (Important)
    2021-06-21
    oval:org.opensuse.security:def:99388
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:118559
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:49080
    P
    Security update for Salt (Important)
    2021-06-21
    oval:org.opensuse.security:def:94387
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:97123
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:73655
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:95937
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:8789
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:92337
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:69677
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:99965
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:109463
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:68747
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:102650
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:117450
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:76545
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:98900
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93750
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:9736
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93087
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:91690
    P
    Security update for SUSE Manager Server 4.0 (Moderate)
    2021-06-21
    oval:org.opensuse.security:def:100629
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:69167
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:107935
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:64533
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:97124
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:95980
    P
    Security update for SUSE Manager Server 4.1 (Moderate)
    2021-06-21
    oval:org.opensuse.security:def:42092
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:8984
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:92536
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:69876
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:38425
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:68765
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:102740
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:118407
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:42858
    P
    Security update for SUSE Manager Client Tools (Important)
    2021-06-21
    oval:org.opensuse.security:def:99095
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93964
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:10106
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93240
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:91950
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:99651
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:109316
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:97125
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:73840
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:96050
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:93414
    P
    (Critical)
    2021-06-21
    oval:org.opensuse.security:def:9352
    P
    Security update for Salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:92735
    P
    Security update for salt (Critical)
    2021-06-21
    oval:org.opensuse.security:def:97063
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:99958
    P
    (Important)
    2021-06-10
    oval:org.opensuse.security:def:100622
    P
    (Important)
    2021-06-10
    oval:org.opensuse.security:def:69124
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:102260
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:1612
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:99645
    P
    (Important)
    2021-06-10
    oval:org.opensuse.security:def:73833
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:100293
    P
    (Important)
    2021-06-10
    oval:org.opensuse.security:def:101452
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:69169
    P
    Security update for salt (Important)
    2021-06-10
    oval:org.opensuse.security:def:64711
    P
    Security update for salt (Important)
    2021-06-10
    BACK
    saltstack salt *
    fedoraproject fedora 33
    fedoraproject fedora 34
    fedoraproject fedora 35